
Experton Group is the leading fully integrated research, advisory and consulting company for mid-sized and large organizations, maximizing the business value of their ICT investments through innovative, neutral and independent expert advice.
Experton Group offers consulting services, market surveys, conferences, seminars and publications related to information and communications technology issues.
Our consulting portfolio includes technology, business processes, management and business co operations, investments and mergers.
The International Organization for Standardization announced it is has developed and is making available a new ISO standard. The new International Standard ISO/IEC 27005:2008 describes the information security risk management process and associated actions that can help firms manage risks.
Focal Points:
Experton Group believes threats from information security risks – whether they are accidental, deliberate, manmade, or natural – will continue to increase as will enterprise vulnerability. Lack of effective information security risk management will expose enterprises to the potential for major financial losses and/or loss of customer confidence. The ISO frameworks, like other frameworks, offer a methodology that companies can use but do not provide the specific processes that are to be implemented. Thus, it can involve a major investment of resources and time to implement the framework in a manner that works for the company. IT executives should evaluate frameworks such as those offered by the Federal Financial Institutions Examination Council (FFIEC) and ISO, and implement an information security risk management governance process.